<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:36:38 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0255 — De multiples vulnérabilités ont été découvertes dans les produits Siemens. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0255</link>
      <description>certfr-2026-avi-0255</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0255</guid>
    </item>
    <item>
      <title>cnvd-2026-13386</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2026-13386</link>
      <description>cnvd-2026-13386</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2026-13386</guid>
    </item>
    <item>
      <title>EUVD-2026-316867</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-316867</link>
      <description>EUVD-2026-316867</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-316867</guid>
    </item>
    <item>
      <title>fkie_cve-2025-40943</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-40943</link>
      <description>&lt;p&gt;Affected devices do not properly sanitize contents of trace files.&#13;
&#13;
This could allow an attacker to inject code through social engineering an authorized user, who has the function right &amp;#34;Read diagnostics&amp;#34;, to import a specially crafted trace file.&#13;
&#13;
The malicious trace file is insufficiently sanitized and malicious code could be executed in the clients browser session and trigger PLC operations via the webserver that the legitimate user is authorized to perform.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Affected devices do not properly sanitize contents of trace files.&#13;
&#13;
This could allow an attacker to inject code through social engineering an authorized user, who has the function right &amp;#34;Read diagnostics&amp;#34;, to import a specially crafted trace file.&#13;
&#13;
The malicious trace file is insufficiently sanitized and malicious code could be executed in the clients browser session and trigger PLC operations via the webserver that the legitimate user is authorized to perform.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-40943</guid>
    </item>
    <item>
      <title>GHSA-v7h2-5j7f-whwh</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v7h2-5j7f-whwh</link>
      <description>&lt;p&gt;Affected devices do not properly sanitize contents of trace files. This could allow an attacker to inject code through social engineering a legitimate user to import a specially crafted trace file&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Affected devices do not properly sanitize contents of trace files. This could allow an attacker to inject code through social engineering a legitimate user to import a specially crafted trace file&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v7h2-5j7f-whwh</guid>
    </item>
    <item>
      <title>ICSA-26-071-04 — Siemens SIMATIC</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-071-04</link>
      <description>&lt;p&gt;Affected devices do not properly sanitize contents of trace files.&#13;
&#13;
This could allow an attacker to inject code through social engineering an authorized user, who has the function right &amp;#34;Read diagnostics&amp;#34;, to import a specially crafted trace file.&#13;
&#13;
The malicious trace file is insufficiently sanitized and malicious code could be executed in the clients browser session and trigger PLC operations via the webserver that the legitimate user is authorized to perform.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Affected devices do not properly sanitize contents of trace files.&#13;
&#13;
This could allow an attacker to inject code through social engineering an authorized user, who has the function right &amp;#34;Read diagnostics&amp;#34;, to import a specially crafted trace file.&#13;
&#13;
The malicious trace file is insufficiently sanitized and malicious code could be executed in the clients browser session and trigger PLC operations via the webserver that the legitimate user is authorized to perform.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-071-04</guid>
    </item>
    <item>
      <title>NCSC-2026-0079 — Kwetsbaarheden verholpen in Siemens producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0079</link>
      <description>NCSC-2026-0079</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0079</guid>
    </item>
    <item>
      <title>SSA-452276 — SSA-452276: Eval Injection Vulnerability in SIMATIC S7-1500</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-452276</link>
      <description>&lt;p&gt;Affected devices do not properly sanitize contents of trace files.&#13;
&#13;
This could allow an attacker to inject code through social engineering an authorized user, who has the function right &amp;#34;Read diagnostics&amp;#34;, to import a specially crafted trace file.&#13;
&#13;
The malicious trace file is insufficiently sanitized and malicious code could be executed in the clients browser session and trigger PLC operations via the webserver that the legitimate user is authorized to perform.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Affected devices do not properly sanitize contents of trace files.&#13;
&#13;
This could allow an attacker to inject code through social engineering an authorized user, who has the function right &amp;#34;Read diagnostics&amp;#34;, to import a specially crafted trace file.&#13;
&#13;
The malicious trace file is insufficiently sanitized and malicious code could be executed in the clients browser session and trigger PLC operations via the webserver that the legitimate user is authorized to perform.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-452276</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0652 — Siemens SIMATIC S7: Schwachstelle ermöglicht Cross-Site Scripting</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0652</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Siemens SIMATIC S7 ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Siemens SIMATIC S7 ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0652</guid>
    </item>
  </channel>
</rss>
